New NGINX Vulnerability Allows Remote Code Execution Attacks
ID: b0d118e3-c234-5e3b-8775-2250c24d6be9
STIX ID: report--b0d118e3-c234-5e3b-8775-2250c24d6be9
Feed Name: Cyber Press
Threat Score
A critical heap buffer overflow (CVE-2026-8711) in the NGINX JavaScript (njs) module (versions 0.9.4–0.9.8) can be triggered via js_fetch_proxy configured with client-controlled variables, causing worker crashes and enabling remote code execution on systems without ASLR; a fix is available in njs 0.9.9 and immediate patching, ASLR enforcement, and configuration hardening are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
